My Oracle Support Banner

Users Are Able To Edit CFAs Even If Permission Is Not Assigned (Doc ID 2398912.1)

Last updated on MAY 22, 2018

Applies to:

Oracle Retail Merchandising System - Version 16.0 and later
Information in this document applies to any platform.

Symptoms

When user has RMS_CUSTOM_FLEX_ATTRIBUTES_INQUIRY_DUTY only associated with current role user is able to edit CFAs.

Steps to recreate:

The issue can be reproduced at will with the following steps:

1. RMS_CUSTOM_FLEX_ATTRIBUTES_INQUIRY_DUTY job has as parent RMS_CUSTOM_FLEX_ATTRIBUTES_MGMT_DUTY
2. Navigate to Application Administration > Custom Flex Attribute. Select Item Master > Display Attributes
3. Notice all operations are available in Actions drop down Add/Edit/Delete
4. Remove RMS_CUSTOM_FLEX_ATTRIBUTES_INQUIRY_DUTY from RMS_CUSTOM_FLEX_ATTRIBUTES_MGMT_DUTY Role
5. Remove RMS_CUSTOM_FLEX_ATTRIBUTES_MGMT_DUTY from Current user Role
6. Add RMS_CUSTOM_FLEX_ATTRIBUTES_INQUIRY_DUTY current user role
7. Navigate to Application Administration > Custom Flex Attribute. Select Item Master > Display Attributes
9. Notice only Edit operation is available in Action form and same fields can be edited as for full access.




Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.